Data processing agreement (DPA)

Last updated: 2026-06-12 · Draft to be reviewed by a lawyer before signature

1. Purpose

This agreement governs the personal data processing performed by the tool on behalf of the customer for the AI visibility service: site scans, file generation, citation tracking.

2. Roles

The customer is the data controller. The tool publisher acts as a processor under article 28 GDPR, on the customer's documented instructions.

3. Sub-processors

Hosting and database in the European Union (Supabase, EU project; Upstash, EU region). Payments by Stripe. Text generation by Anthropic and Mistral AI: only public information from the scanned site is sent to them, never account data. The up-to-date list is available on request.

4. Security

Encryption in transit, per-account isolation (row level security), API keys stored server side, minimisation: only the data needed for the service is kept.

5. Duration and return

Data is kept for the duration of the contract. On termination or request it is deleted: account deletion erases sites, scans, generated files and measures.

6. Assistance and rights

The publisher assists the customer with data subject requests (access, erasure, portability) through the built-in export and deletion functions, or by email.